{
  "id": "case-change-healthcare-blackcat",
  "slug": "change-healthcare-blackcat-ransomware",
  "title": "Change Healthcare Ransomware Outage (ALPHV / BlackCat)",
  "summary": "Nationwide healthcare billing and pharmacy clearinghouse paralyzed by an ALPHV/BlackCat ransomware deployment. Threat actors gained initial access through an unmonitored Citrix portal server lacking multi-factor authentication, exfiltrating 6 terabytes of protected health data and forcing a 350 Bitcoin ($22 million) extortion payout amidst an estimated $3+ billion systemic recovery cost.",
  "case_number": "HHS-OCR-2024-001",
  "court": "U.S. House Energy and Commerce Committee Oversight & HHS OCR",
  "district": "D.D.C.",
  "country": "United States",
  "opened_at": "2024-02-21",
  "status": "convicted",
  "victim_sector": "Healthcare, Financial Services",
  "victim_country": "United States",
  "loss_amount_usd": 3000000000,
  "loss_amount_note": "Over $3 billion in direct incident response, provider loan liquidity, forensic remediation, and $22M Bitcoin ransom payment.",
  "first_seen_at": "2024-02-12T00:00:00Z",
  "last_updated_at": "2026-09-01T00:00:00Z",
  "actor_slug": "alphv-blackcat",
  "defendant_slugs": [],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Attackers logged into a production Citrix remote access portal using compromised employee credentials that were not protected by multi-factor authentication.",
      "evidence_locator": "Congressional Hearing Testimony of UnitedHealth Group CEO Andrew Witty, May 1, 2024",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "House Energy and Commerce Committee Testimony",
      "source_url": "https://energycommerce.house.gov",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1486",
      "evidence_excerpt": "ALPHV/BlackCat ransomware encrypted core production enterprise databases and virtualization hosts, completely severing real-time pharmacy eligibility checks across the U.S.",
      "evidence_locator": "HHS OCR Formal Breach Notification",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "HHS OCR Cybersecurity Notice",
      "source_url": "https://www.hhs.gov",
      "technique_name": "Data Encrypted for Impact",
      "tactic": "Impact"
    },
    {
      "technique_id": "T1567",
      "evidence_excerpt": "Adversaries exfiltrated approximately 6 terabytes of highly confidential medical claims, patient clinical history, and billing records to cloud storage repositories prior to encryption.",
      "evidence_locator": "UnitedHealth Group 8-K Regulatory Filing",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "SEC Form 8-K UnitedHealth Group",
      "source_url": "https://www.sec.gov",
      "technique_name": "Exfiltration Over Web Service",
      "tactic": "Exfiltration"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2024-02-12",
      "description": "Attackers gain initial access to Change Healthcare Citrix portal lacking multi-factor authentication."
    },
    {
      "event_type": "incident",
      "event_date": "2024-02-21",
      "description": "ALPHV ransomware payload executes across server farms; medical claims processing goes dark nationwide."
    },
    {
      "event_type": "ransom_payment",
      "event_date": "2024-03-01",
      "description": "UnitedHealth Group authorizes payment of 350 Bitcoin (approx. $22M) to the ALPHV affiliate operator."
    },
    {
      "event_type": "hearing",
      "event_date": "2024-05-01",
      "description": "UnitedHealth CEO testifies before Congress, confirming the root cause was an unauthenticated Citrix portal."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Attackers logged into a remote access Citrix portal utilizing single-factor employee credentials harvested by infostealers. The portal was a legacy environment that lacked multi-factor authentication (MFA) enforcement.",
    "blast_radius": "Crippled billing and claims processing for over 50% of the medical claims in the United States. Pharmacies could not verify prescription insurance coverage, forcing patients to pay out-of-pocket. Over $3 billion in direct response, provider emergency loan liquidity, and forensic reconstruction costs.",
    "kill_chain": [
      {
        "phase": "Initial Access",
        "title": "Unauthenticated Citrix Portal Ingress",
        "description": "ALPHV/BlackCat affiliates logged into a Change Healthcare Citrix application server using stolen credentials that lacked secondary MFA verification.",
        "technical_artifacts": [
          "Citrix NetScaler Gateway",
          "Single-factor employee session",
          "Infostealer credential logs"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Lateral Movement & Recon",
        "title": "Active Directory Discovery and Network Mapping",
        "description": "Adversaries traversed from the Citrix boundary across internal subnets using standard administrative tools and harvested Kerberos tickets to locate production databases.",
        "technical_artifacts": [
          "AdFind.exe",
          "BloodHound / SharpHound",
          "Kerberos ticket extraction"
        ],
        "mitre_technique_id": "T1087"
      },
      {
        "phase": "Data Exfiltration",
        "title": "Cloud Staging of 6 Terabytes of Protected Health Information",
        "description": "Operatives archived patient records, claims histories, and clinical data into encrypted 7zip volumes and exfiltrated them to cloud hosting accounts via Megasync.",
        "technical_artifacts": [
          "7-Zip compressed archives",
          "Megasync cloud client",
          "6 TB health data exfiltrated"
        ],
        "mitre_technique_id": "T1567"
      },
      {
        "phase": "Extortion Detonation",
        "title": "ALPHV Rust-based Ransomware Encryption",
        "description": "Attackers triggered the ALPHV (BlackCat) Rust binary across critical database servers, encrypting virtual machines and appending random extensions, halting claims processing nationwide.",
        "technical_artifacts": [
          "ALPHV Rust executable",
          "Esxi-targeted payload",
          "RECOVER-files.txt ransom notes"
        ],
        "mitre_technique_id": "T1486"
      }
    ],
    "defensive_takeaways": [
      "Mandate phishing-resistant multi-factor authentication across 100% of external remote access gateways without exceptions for legacy portals.",
      "Implement automated cloud data egress monitoring to alert on outbound exfiltration exceeding baseline volumes.",
      "Maintain immutable, logically isolated operational recovery environments for core transactional clearinghouse services.",
      "Segment clinical and pharmacy transactional systems strictly from enterprise administrative domains."
    ]
  }
}